Topic · Security
Best bug bounty skills for Claude Code, Codex and other agents.
- skills
- 75
- official
- 4
Bug bounty skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns. | awarexone/ | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | 3 days ago |
| 2 | Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. | awarexone/ | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | 3 days ago |
| 3 | Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. | j3ssie/ | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 4 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 5 | Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet. | awarexone/ | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | 3 days ago |
| 6 | A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization. | tradecatlabs/ | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | today |
| 7 | Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 8 | 8.Flounder Operates Flounder, an autonomous white-hat security auditor. | adshao/ | 519 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | 2 days ago |
| 9 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. | elementalsouls/ | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 12 | 12.Write Structure and per-section format reference for a bug bounty report, aligned with YesWeHack's official guidance. | yeswehack/ | 107 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 13 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 14 | 移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。 | s7safe/ | 210 | — | ~631 | Automated safety check: Pass | No licence | 5 mo ago |
| 15 | Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations. | Gabson0x/ | 443 | — | ~1.2k | Automated safety check: Pass | No licence | 21 days ago |
| 17 | 17.Triage Self-validates a bug bounty report draft before submission. An agent skill from yeswehack/claude-kit. | yeswehack/ | 107 | — | ~1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 18 | Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews. | tradecatlabs/ | 17k | 2 repos | ~10k | Automated safety check: Pass | MIT | today |
| 19 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | today |
| 20 | Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting. | tradecatlabs/ | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | today |
| 21 | Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus. | tradecatlabs/ | 17k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | today |
| 22 | Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring. | tradecatlabs/ | 17k | 2 repos | ~2.5k | Automated safety check: Pass | MIT | today |
| 23 | Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target. | tradecatlabs/ | 17k | 2 repos | ~2.2k | Automated safety check: Pass | MIT | today |
| 24 | Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~524 | Automated safety check: Pass | No licence | 2 mo ago |
| 25 | Spawning and hardening scan containers from the recon orchestrator: the security flags that look correct and break the container, and the sibling bind-mount path handling. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 26 | Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early. | awarexone/ | 5.3k | 3 repos | ~3.4k | Automated safety check: Pass | MIT | 3 days ago |
| 27 | A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every… | mtarcure/ | 163 | — | ~3.6k | Automated safety check: Pass | MIT | 17 days ago |
| 28 | Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~550 | Automated safety check: Pass | No licence | 2 mo ago |
| 29 | Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist. | awarexone/ | 5.3k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | 3 days ago |
| 30 | 30.Nmap Recon Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools | CommonHuman-Lab/ | 157 | — | ~639 | Automated safety check: Pass | Unknown | today |
| 31 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 32 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 33 | Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field. | samugit83/ | 3k | — | ~2.2k | Automated safety check: Pass | MIT | today |
| 34 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | today |
| 35 | A skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a… | serejaris/ | 229 | — | ~3.4k | Automated safety check: Notes | MIT | today |
| 36 | Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. | fabricioctelles/ | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 37 | 37.Write Report Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus. | bugbountywithmarco/ | 122 | — | ~585 | Automated safety check: Pass | No licence | 2 mo ago |
| 38 | Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. | Encod3d-Sec/ | 329 | — | ~611 | Automated safety check: Pass | MIT | 1 mo ago |
| 39 | Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently… | samugit83/ | 3k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 40 | Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 41 | Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation… | provos/ | 613 | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 42 | 42.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 3 days ago |
| 43 | 43.Gotchas Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps. | yeswehack/ | 107 | — | ~4.3k | Automated safety check: Warn | GPL-3.0 | 1 mo ago |
| 44 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 45 | 45.Web Recon Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f | CommonHuman-Lab/ | 157 | — | ~907 | Automated safety check: Pass | Unknown | today |
| 46 | Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi | sickn33/ | 47k | 1 repo | ~3.2k | Automated safety check: Pass | MIT | today |
| 47 | Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. | sickn33/ | 47k | 1 repo | ~5.4k | Automated safety check: Pass | MIT | today |
| 48 | 48.Bug Bounty Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling… | awarexone/ | 5.3k | — | ~20k | Automated safety check: Warn | MIT | 3 days ago |
Questions, answered from the data.
What is the best bug bounty skill?
Web3 Smart Contract Audit from awarexone/Agentic-Bug-Hunter ranks first of the 75 bug bounty skills listed here, with the highest score: its repository has 5.3k GitHub stars, 3 other GitHub owners carry a copy, its SKILL.md loads about 4.5k tokens and it passes the automated safety check with no findings. Next come Bug Bounty Hunting Methodology and Metabigor OSINT Recon.
Which bug bounty skills are official?
4 of the 75 bug bounty skills are official, published by the vendor's own GitHub organization: Security Analysis, Vulnerability Triage Brocards, Audit Context Building and Auditing Hackerone Vulns.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38